CWE-290 · 718 kayıt
Authentication Bypass by Spoofing
Bu sınıftaki CVE’ler
718 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2024-4358Silahlaştırılmış | Registration Authentication Bypass Vulnerabilitytelerik · report server 2024 · CWE-290 | Kritik9,8 | KEV | %97,5 | 29 May 2024 |
98Hemen | CVE-2022-24112Silahlaştırılmış | apisix/batch-requests plugin allows overwriting the X-REAL-IP headerapache · apisix · CWE-290 | Kritik9,8 | KEV | %96,1 | 11 Şub 2022 |
98Hemen | CVE-2022-23131Silahlaştırılmış | Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAMLzabbix · zabbix · CWE-290 | Kritik9,8 | KEV | %95,7 | 13 Oca 2022 |
88Hemen | CVE-2024-54085Silahlaştırılmış | Redfish Authentication Bypassami · megarac sp-x · CWE-290 | Kritik10,0 | KEV | %60,7 | 11 Mar 2025 |
64Bu hafta | CVE-2021-29441Kavram kanıtı | Authentication bypassalibaba · nacos · CWE-290 | Kritik9,8 | — | %83,5 | 27 Nis 2021 |
61Bu hafta | CVE-2023-50224Silahlaştırılmış | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerabilitytp-link · tl-wr841n firmware · CWE-290 | Orta6,5 | KEV | %15,6 | 2 May 2024 |
60Bu hafta | CVE-2020-7388Silahlaştırılmış | Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofingsage · adxadmin · CWE-290 | Kritik9,8 | — | %69,4 | 22 Tem 2021 |
54Planlayın | CVE-2021-34646Kavram kanıtı | Booster for WooCommerce <= 5.4.3 Authentication Bypassbooster · booster for woocommerce · CWE-290 | Kritik9,8 | — | %50,9 | 30 Ağu 2021 |
53Planlayın | CVE-2019-1234İstismar yok | A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.microsoft · azure stack · CWE-290 | Yüksek7,5 | — | %75,2 | 12 Kas 2019 |
50Planlayın | CVE-2018-7842Kavram kanıtı | A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Moschneider-electric · modicon m580 firmware · CWE-290 | Kritik9,8 | — | %35,0 | 22 May 2019 |
48Planlayın | CVE-2021-31195Kavram kanıtı | Microsoft Exchange Server Remote Code Execution Vulnerabilitymicrosoft · exchange server · CWE-290 | Orta6,5 | — | %73,7 | 11 May 2021 |
47Planlayın | CVE-2025-49002Kavram kanıtı | Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerabilitydataease · dataease · CWE-290 | Yüksek8,2 | — | %50,3 | 3 Haz 2025 |
44Planlayın | CVE-2023-30803İstismar yok | Sangfor Next-Gen Application Firewall Authentication Bypasssangfor · next-gen application firewall · CWE-290 | Kritik9,8 | — | %18,2 | 10 Eki 2023 |
42Planlayın | CVE-2018-5353Kavram kanıtı | The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalatezohocorp · manageengine adselfservice plus · CWE-290 | Kritik9,8 | — | %11,1 | 30 Eyl 2020 |
42Planlayın | CVE-2022-3180İstismar yok | WPGateway <= 3.5 - Unauthenticated Privilege Escalationwpgateway · wpgateway · CWE-290 | Kritik9,8 | — | %9,2 | 11 Şub 2025 |
41Planlayın | CVE-2022-34689İstismar yok | Windows CryptoAPI Spoofing Vulnerabilitymicrosoft · windows 10 · CWE-290 | Yüksek7,5 | — | %37,9 | 11 Eki 2022 |
41Planlayın | CVE-2009-1048İstismar yok | The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7snom · snom 300 firmware · CWE-290 | Kritik9,8 | — | %6,4 | 14 Ağu 2009 |
41Planlayın | CVE-2019-16871İstismar yok | Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remotebeckhoff · twincat · CWE-290 | Kritik9,8 | — | %5,3 | 19 Ara 2019 |
40Planlayın | CVE-2024-12108İstismar yok | WhatsUp Gold - Public API signing key rotation issueprogress · whatsup gold · CWE-290 | Kritik9,6 | — | %6,8 | 31 Ara 2024 |
40Planlayın | CVE-2017-14375İstismar yok | EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.emc · solutions enabler · CWE-290 | Kritik9,8 | — | %4,8 | 31 Eki 2017 |
40Planlayın | CVE-2023-3128Kavram kanıtı | Grafana is validating Azure AD accounts based on the email claim.grafana · grafana · CWE-290 | Kritik9,8 | — | %4,0 | 22 Haz 2023 |
40Planlayın | CVE-2018-15715İstismar yok | Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vzoom · zoom · CWE-290 | Kritik9,8 | — | %3,5 | 30 Kas 2018 |
40Planlayın | CVE-2020-22001İstismar yok | HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header wihomeautomation project · homeautomation · CWE-290 | Kritik9,8 | — | %3,4 | 27 Nis 2021 |
40Planlayın | CVE-2019-20790İstismar yok | OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situationstrusteddomain · opendmarc · CWE-290 | Kritik9,8 | — | %2,6 | 27 Nis 2020 |
40Planlayın | CVE-2017-14003İstismar yok | An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and plavalink · ether-serial link firmware · CWE-290 | Kritik9,8 | — | %2,6 | 11 Eki 2017 |
- CVE-2024-435898Hemen
Registration Authentication Bypass Vulnerability
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97telerik · report server 202429 May 2024
- CVE-2022-2411298Hemen
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96apache · apisix11 Şub 2022
- CVE-2022-2313198Hemen
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %96zabbix · zabbix13 Oca 2022
- CVE-2024-5408588Hemen
Redfish Authentication Bypass
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %61ami · megarac sp-x11 Mar 2025
- CVE-2021-2944164Bu hafta
Authentication bypass
KritikCVSS 9,8Kavram kanıtıEPSS %83alibaba · nacos27 Nis 2021
- CVE-2023-5022461Bu hafta
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %16tp-link · tl-wr841n firmware2 May 2024
- CVE-2020-738860Bu hafta
Sage X3 AdxAdmin Unauthenticated Command Execution Bypass by Spoofing
KritikCVSS 9,8SilahlaştırılmışEPSS %69sage · adxadmin22 Tem 2021
- CVE-2021-3464654Planlayın
Booster for WooCommerce <= 5.4.3 Authentication Bypass
KritikCVSS 9,8Kavram kanıtıEPSS %51booster · booster for woocommerce30 Ağu 2021
- CVE-2019-123453Planlayın
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.
YüksekCVSS 7,5İstismar yokEPSS %75microsoft · azure stack12 Kas 2019
- CVE-2018-784250Planlayın
A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Mo
KritikCVSS 9,8Kavram kanıtıEPSS %35schneider-electric · modicon m580 firmware22 May 2019
- CVE-2021-3119548Planlayın
Microsoft Exchange Server Remote Code Execution Vulnerability
OrtaCVSS 6,5Kavram kanıtıEPSS %74microsoft · exchange server11 May 2021
- CVE-2025-4900247Planlayın
Dataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability
YüksekCVSS 8,2Kavram kanıtıEPSS %50dataease · dataease3 Haz 2025
- CVE-2023-3080344Planlayın
Sangfor Next-Gen Application Firewall Authentication Bypass
KritikCVSS 9,8İstismar yokEPSS %18sangfor · next-gen application firewall10 Eki 2023
- CVE-2018-535342Planlayın
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate
KritikCVSS 9,8Kavram kanıtıEPSS %11zohocorp · manageengine adselfservice plus30 Eyl 2020
- CVE-2022-318042Planlayın
WPGateway <= 3.5 - Unauthenticated Privilege Escalation
KritikCVSS 9,8İstismar yokEPSS %9wpgateway · wpgateway11 Şub 2025
- CVE-2022-3468941Planlayın
Windows CryptoAPI Spoofing Vulnerability
YüksekCVSS 7,5İstismar yokEPSS %38microsoft · windows 1011 Eki 2022
- CVE-2009-104841Planlayın
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7
KritikCVSS 9,8İstismar yokEPSS %6snom · snom 300 firmware14 Ağu 2009
- CVE-2019-1687141Planlayın
Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attacker to achieve Remote
KritikCVSS 9,8İstismar yokEPSS %5beckhoff · twincat19 Ara 2019
- CVE-2024-1210840Planlayın
WhatsUp Gold - Public API signing key rotation issue
KritikCVSS 9,6İstismar yokEPSS %7progress · whatsup gold31 Ara 2024
- CVE-2017-1437540Planlayın
EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.
KritikCVSS 9,8İstismar yokEPSS %5emc · solutions enabler31 Eki 2017
- CVE-2023-312840Planlayın
Grafana is validating Azure AD accounts based on the email claim.
KritikCVSS 9,8Kavram kanıtıEPSS %4grafana · grafana22 Haz 2023
- CVE-2018-1571540Planlayın
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are v
KritikCVSS 9,8İstismar yokEPSS %3zoom · zoom30 Kas 2018
- CVE-2020-2200140Planlayın
HomeAutomation 3.3.2 suffers from an authentication bypass vulnerability when spoofing client IP address using the X-Forwarded-For header wi
KritikCVSS 9,8İstismar yokEPSS %3homeautomation project · homeautomation27 Nis 2021
- CVE-2019-2079040Planlayın
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations
KritikCVSS 9,8İstismar yokEPSS %3trusteddomain · opendmarc27 Nis 2020
- CVE-2017-1400340Planlayın
An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and p
KritikCVSS 9,8İstismar yokEPSS %3lavalink · ether-serial link firmware11 Eki 2017